security@mozilla.org reports:
+++ +Memory safety bugs present in Firefox 135 and Thunderbird + 135. Some of these bugs showed evidence of memory corruption + and we presume that with enough effort some of these could + have been exploited to run arbitrary code.
+
security@mozilla.org reports:
+++ +CVE-2025-1938: Memory safety bugs present in Firefox 135, + Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. + Some of these bugs showed evidence of memory corruption and + we presume that with enough effort some of these could have + been exploited to run arbitrary code.
+CVE-2025-1935: A web page could trick a user into setting + that site as the default handler for a custom URL protocol.
+CVE-2025-1934: It was possible to interrupt the processing + of a RegExp bailout and run additional JavaScript, potentially + triggering garbage collection when the engine was not + expecting it.
+
security@mozilla.org reports:
+++ +Memory safety bugs present in Firefox 135, Thunderbird 135, + Firefox ESR 115.20, Firefox ESR 128.7, and Thunderbird 128.7. + Some of these bugs showed evidence of memory corruption and + we presume that with enough effort some of these could have + been exploited to run arbitrary code.
+
security@mozilla.org reports:
+++ +It was possible to cause a use-after-free in the content + process side of a WebTransport connection, leading to a + potentially exploitable crash.
+
security@mozilla.org reports:
+++ +On 64-bit CPUs, when the JIT compiles WASM i32 return + values they can pick up bits from left over memory. + This can potentially cause them to be treated as a different + type.
+